Malicious
bccab38d9c9a08297941cbad5da9d539
VBScript
MD5: bccab38d9c9a08297941cbad5da9d539
Size: 175 B
text/vbscript
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
| MD5 | bccab38d9c9a08297941cbad5da9d539 |
| Sha1 | 4c8a93abafc9fe108161960412f2bfeef69ea452 |
| Sha256 | 4f75b70ef696ec050a6ee5f6be7bd7be445526aa5a3b23f5340ecc097281ca11 |
| Sha384 | da85149a993f5b5e894fd365081d547ab606ff3490cc906e26d3dc85c4224610367882d26afb5ec64365a4a6b0e7d102 |
| Sha512 | 9c375f584fe74fe01697c1a65bca2a26655e81d3b12a8fdd4dcb5e845b32da5f8a36f160df1cb3fb65d08551e511ec4b55fce7b1685ef4efd3aa49eac29e37f9 |
| SSDeep | 3:jblYFFEm8nhQBgSSJJFIGF7dN0PbKuV2qbqSgBJlQpaKnJvXpv:ju3NqhMs8GFIFOfS0G |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
scr:vbs~T1027~T1059.005>scr:bat>scr:ps1~T1027~T1059.001~T1105
Shape
scr:vbs>scr:bat>scr:ps1
malicious
3 nodes
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | http:/huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée
UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
irm "huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
| Config. Field | Value |
|---|---|
| URL in PowerShell #1 | http:/huhuhuhuhuhuhuhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée
UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
bccab38d9c9a08297941cbad5da9d539
URLs in VB Code - #1
URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
bccab38d9c9a08297941cbad5da9d539
Deobfuscated PowerShell
UNKNWOWNmalicious
irm "huhuhuhuhuhuhuhuhuhuhu
bccab38d9c9a08297941cbad5da9d539 › bccab38d9c9a08297941cbad5da9d539.deobfuscated.vbs › [Command #0] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.